<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 15:18:33 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-55950 — DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-55950</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Erlang OTP&lt;/p&gt;
&lt;p&gt;Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener.&lt;/p&gt;
&lt;p&gt;A DTLS server listener uses a single shared dtls_packet_demux gen_server process to route incoming UDP datagrams to the correct connection handler. When a DTLS client reconnects rapidly from the same source address and port (sending multiple ClientHello messages in quick succession), a race condition in the demux&amp;#39;s internal gb_trees key-value store causes a {key_exists, {old, Client}} crash, terminating the demux process. Because the demux is shared across all DTLS associations on that listener, its crash immediately kills every active DTLS session, not just the attacker&amp;#39;s.&lt;/p&gt;
&lt;p&gt;The attack is pre-authentication: the attacker only needs to send UDP datagrams containing valid ClientHello messages from the same source IP and port before the intermediate DOWN monitor message is processed by the gen_server. No credentials, no completed handshake, and no special configuration are required, and the crash can be repeated indefinitely to create a persistent denial of service for all clients of that listener.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program file lib/ssl/src/dtls_packet_demux.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 25.3 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 10.9 before 11.7.3, 11.6.0.3 and 11.2.12.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Erlang OTP&lt;/p&gt;
&lt;p&gt;Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener.&lt;/p&gt;
&lt;p&gt;A DTLS server listener uses a single shared dtls_packet_demux gen_server process to route incoming UDP datagrams to the correct connection handler. When a DTLS client reconnects rapidly from the same source address and port (sending multiple ClientHello messages in quick succession), a race condition in the demux&amp;#39;s internal gb_trees key-value store causes a {key_exists, {old, Client}} crash, terminating the demux process. Because the demux is shared across all DTLS associations on that listener, its crash immediately kills every active DTLS session, not just the attacker&amp;#39;s.&lt;/p&gt;
&lt;p&gt;The attack is pre-authentication: the attacker only needs to send UDP datagrams containing valid ClientHello messages from the same source IP and port before the intermediate DOWN monitor message is processed by the gen_server. No credentials, no completed handshake, and no special configuration are required, and the crash can be repeated indefinitely to create a persistent denial of service for all clients of that listener.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program file lib/ssl/src/dtls_packet_demux.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 25.3 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 10.9 before 11.7.3, 11.6.0.3 and 11.2.12.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-55950</guid>
    </item>
    <item>
      <title>USN-8901-1 — erlang vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8901-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Wander Nauta discovered that Erlang incorrectly handled absolute paths when
extracting zip archives. An attacker could possibly use this issue to write
arbitrary files outside of the intended directory. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-4748)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SFTP server did not properly limit the
size of packets. A remote attacker could possibly use this issue to cause
Erlang to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS. (CVE-2025-26618)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SSH server did not properly limit the
length of algorithm names in key exchange messages. A remote attacker could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2025-30211)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang TFTP server incorrectly handled certain
file paths. A remote attacker could possibly use this issue to access files
outside of the intended directory. (CVE-2026-21620)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SFTP server incorrectly validated paths
against the configured root directory. An authenticated user could possibly
use this issue to access files outside of the root directory.
(CVE-2026-23942)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SSH server enabled zlib compression by
default and did not limit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Wander Nauta discovered that Erlang incorrectly handled absolute paths when
extracting zip archives. An attacker could possibly use this issue to write
arbitrary files outside of the intended directory. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-4748)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SFTP server did not properly limit the
size of packets. A remote attacker could possibly use this issue to cause
Erlang to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and
Ubuntu 18.04 LTS. (CVE-2025-26618)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SSH server did not properly limit the
length of algorithm names in key exchange messages. A remote attacker could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. This issue only affected Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2025-30211)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang TFTP server incorrectly handled certain
file paths. A remote attacker could possibly use this issue to access files
outside of the intended directory. (CVE-2026-21620)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SFTP server incorrectly validated paths
against the configured root directory. An authenticated user could possibly
use this issue to access files outside of the root directory.
(CVE-2026-23942)&lt;/p&gt;
&lt;p&gt;It was discovered that the Erlang SSH server enabled zlib compression by
default and did not limit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8901-1</guid>
    </item>
  </channel>
</rss>
